Insufficient Validation in Bitdefender Update Server and BEST Relay Components
CVE-2020-15297
7.1HIGH
What is CVE-2020-15297?
The vulnerability in Bitdefender's Update Server and BEST Relay components allows an unprivileged attacker to bypass existing mitigations, enabling unauthorized interaction with network hosts. This issue specifically impacts versions of Bitdefender Endpoint Security Tools released prior to 6.6.20.294. Users of these versions may face risks as the attacker gains the ability to execute unintended commands or access sensitive network resources.
Affected Version(s)
Bitdefender Update Server < 6.6.20.294
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
